11 Sep
|
Version 1
|
Bengaluru
11 Sep
Version 1
Bengaluru
Job Description
We are seeking a Cyber Threat Exposure Analyst to support our exposure management programme across the estate. The role spans vulnerability management, attack surface management, cloud security posture, and secure development practice. Working as a fully contributing team member, you will own end-to-end vulnerability lifecycle activity, maintain prioritised exposure views, and communicate risk clearly to internal stakeholders. You operate with limited supervision, take clear ownership of your assignments, and consistently deliver to a high standard of quality.
Key Responsibilities
Attack Surface Management (ASM / EASM)
- Maintain a continuous inventory of Internet-facing assets, shadow IT, domains, subdomains, certificates, cloud services, APIs, and third-party-hosted assets.
- Operate EASM/CAASM tooling to surface unowned or unmanaged assets and route them to the correct owner.
- Enrich attack surface findings with threat intelligence, active exploitation trends, and KEV data to support prioritisation.
- Proactively identify gaps in asset coverage and bring forward improvement ideas without waiting to be directed.
Vulnerability Management
- Own the end-to-end vulnerability lifecycle: identification, risk-based triage, remediation tracking, and closure validation.
- Apply CVSS, EPSS, and business context to set remediation SLAs and escalation paths.
- Maintain vulnerability management policies, standards, and reporting cadence aligned to ISO 27001 and NIST CSF.
- Break down complex vulnerability backlogs into prioritised, actionable components and drive them to closure with minimal supervision.
Cloud Security Posture Management (CSPM)
- Monitor cloud misconfigurations, identity risk, and posture drift across AWS, Azure, and OCI.
- Partner with cloud platform teams to remediate CSPM findings and reduce recurring misconfiguration classes.
- Extend CSPM coverage as new cloud services, apps, and workloads are onboarded.
- Build and maintain strong working relationships with platform and engineering teams; negotiate remediation timelines and handle pushback constructively.
CTEM / Exposure Management
- Operate the Scope, Discover, Prioritise, Validate, and Mobilise phases of the CTEM programme.
- Consolidate attack surface, vulnerability, and posture data into a single exposure view for stakeholders.
- Track and report exposure reduction metrics against agreed KPIs, maintaining accurate and well-organised records across all workstreams.
Secure SDLC
- Embed security requirements, threat modelling, and secure code review checkpoints into the SDLC.
- Work with engineering teams to reduce vulnerability injection at source rather than relying only on downstream remediation.
- Maintain secure-by-design standards and guidance for development teams.
Pentest & Purple Team Support
- Support the commission and management of third-party penetration testing and purple team engagements.
- Review scope, rules of engagement, and quality of third-party findings before acceptance.
- Translate external test results into prioritised, actionable remediation guidance for internal teams.
Reporting & Stakeholder Communication
- Produce dashboards and reports translating technical exposure data into business risk language for senior stakeholders.
- Present exposure trends, remediation progress, and residual risk to management and audit/compliance functions.
- Support audit and certification cycles (ISO 27001, Cyber Essentials Plus, SOC 1, client MSP audits) with evidence of exposure management practice.
- Adapt communication style to the audience; explain technical risk clearly to non-technical colleagues and business stakeholders.
Ways of Working
- Meet all team commitments and deadlines; support colleagues encountering blockers and contribute to a collaborative team environment.
- Seek out and act on feedback; treat problems as learning opportunities and continuously update skills and knowledge.
- Adapt readily to changing priorities, current tooling, and evolving threat landscapes without disruption to delivery quality.
- Live and demonstrate Version 1 Core Values in everyday work, acting as a visible example for more junior colleagues.
📌 Cyber Threat Exposure Management Analyst (Bengaluru)
🏢 Version 1
📍 Bengaluru